CVE-2020-5577

HIGH

Movable Type <7.2.1, <6.5.3, <6.3.11 - Path Traversal

Title source: llm
STIX 2.1

Description

Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS 7), Movable Type 6.5.3 and earlier (Movable Type 6.5), Movable Type Advanced 6.5.3 and earlier (Movable Type Advanced 6.5), Movable Type 6.3.11 and earlier (Movable Type 6.3), Movable Type Advanced 6.3.11 and earlier (Movable Type 6.3), Movable Type Premium 1.29 and earlier, and Movable Type Premium Advanced 1.29 and earlier) allow remote authenticated attackers to upload arbitrary files and execute a php script via unspecified vectors.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://movabletype.org/news/2020/05/mt-730-660-6312-released.html
Third Party Advisory, VDB Entry x_refsource_misc
https://jvn.jp/en/jp/JVN28806943/index.html

Scores

CVSS v3 8.8
EPSS 0.0085
EPSS Percentile 75.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (3)
sixapart/movable_type < 1.29 (2 CPE variants)
sixapart/movable_type 6.3 - 6.3.11
sixapart/movable_type 7.0 - 7.2.1
Published May 14, 2020
Tracked Since Feb 18, 2026